<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SOAR101 question regarding passing variables in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/SOAR101-question-regarding-passing-variables/m-p/744042#M1701</link>
    <description>&lt;P&gt;Just getting started with SOAR and I am encountering a scenario where I obviously don't understand the concept enough. I could use a push in the right direction to understand how I'm supposed to pass output from a Splunk action block to a decision or utility block. Logic is as follows:&lt;BR /&gt;&lt;BR /&gt;1. We utilize a Splunk -- Timer asset to schedule execution of playbook at certain time&lt;/P&gt;&lt;P&gt;2. First block is a Splunk query action block; basic SPL is&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=custom_index usernames=* | table usernames, emailAddresses, userScore&lt;/LI-CODE&gt;&lt;P&gt;3. I want to pass the usernames to a decision block, and this is where I get lost. I see event choices, and CEF fields, etc. as options, but nothing explicitly stated for "usernames". Am I supposed to custom code a solution using action_result.data, and if so, can I get a hint on how to do so? (this wasn't covered in my creating playbooks course)&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2025 18:43:59 GMT</pubDate>
    <dc:creator>NuttyBrown</dc:creator>
    <dc:date>2025-04-11T18:43:59Z</dc:date>
    <item>
      <title>SOAR101 question regarding passing variables</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/SOAR101-question-regarding-passing-variables/m-p/744042#M1701</link>
      <description>&lt;P&gt;Just getting started with SOAR and I am encountering a scenario where I obviously don't understand the concept enough. I could use a push in the right direction to understand how I'm supposed to pass output from a Splunk action block to a decision or utility block. Logic is as follows:&lt;BR /&gt;&lt;BR /&gt;1. We utilize a Splunk -- Timer asset to schedule execution of playbook at certain time&lt;/P&gt;&lt;P&gt;2. First block is a Splunk query action block; basic SPL is&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=custom_index usernames=* | table usernames, emailAddresses, userScore&lt;/LI-CODE&gt;&lt;P&gt;3. I want to pass the usernames to a decision block, and this is where I get lost. I see event choices, and CEF fields, etc. as options, but nothing explicitly stated for "usernames". Am I supposed to custom code a solution using action_result.data, and if so, can I get a hint on how to do so? (this wasn't covered in my creating playbooks course)&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:43:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/SOAR101-question-regarding-passing-variables/m-p/744042#M1701</guid>
      <dc:creator>NuttyBrown</dc:creator>
      <dc:date>2025-04-11T18:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: SOAR101 question regarding passing variables</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/SOAR101-question-regarding-passing-variables/m-p/744059#M1702</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;To pass the usernames field from your Splunk action block to a decision or utility block in SOAR, use the custom output paths from the action result.&lt;/P&gt;&lt;P&gt;In the decision block, reference the field as &lt;EM&gt;&lt;STRONG&gt;action_result.data.*.usernames&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;The Splunk action block returns results as a list of dictionaries under action_result.data.&lt;/P&gt;&lt;P&gt;The .*. wildcard iterates over each result, accessing the usernames field from each row.&lt;/P&gt;&lt;P&gt;Field names are case-sensitive and must match exactly as returned by your SPL.&lt;/P&gt;&lt;P&gt;If your SPL returns multiple rows, the path will return a list of values.&lt;/P&gt;&lt;P&gt;The following docs pages may also be useful:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SOAR/current/Playbook/SpecifyData" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SOAR/current/Playbook/SpecifyData&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SOAR/current/DevelopApps/DataPath" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SOAR/current/DevelopApps/DataPath&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Phantom/4.10.7/PlaybookAPI/Datapaths" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Phantom/4.10.7/PlaybookAPI/Datapaths&lt;/A&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt; &lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt; If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 12 Apr 2025 14:01:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/SOAR101-question-regarding-passing-variables/m-p/744059#M1702</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-04-12T14:01:18Z</dc:date>
    </item>
  </channel>
</rss>

